Home / Sep 26, 2026 / Story
0
#3 The Hacker News general September 25, 2026 at 10:14 UTC

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

By [email protected] (The Hacker News)

AI Summary

CVE-2026-48842 (CVSS 8.1), a pre-authentication SQL injection vulnerability in Roundcube Webmail's virtuser_query plugin, is being actively exploited in the wild according to the Canadian Centre for Cyber Security. The flaw affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, and stems from a preg_replace() backslash handling issue that requires no authentication to exploit. Organizations running Roundcube for email should patch immediately given active exploitation.

Relevance score: 84.0/100

# More from September 26